
What Should Governors Actually Receive in an IT Report?
asitplan Strategy Team
Author
Rob Lloyd
Technical Reviewer
06 August 2026
Last Reviewed
Headteachers, IT leads, and governors
Target Audience
The Context
Governors and trustees carry ultimate accountability for a school's cyber resilience, safeguarding infrastructure, and IT expenditure. Yet, they are frequently presented with IT reports consisting of meaningless operational metrics, such as "we closed 450 helpdesk tickets this term" or "server uptime was 99%". This data does not help them govern.
Who This Guide is For
Headteachers, strategic IT leads, and chairs of governors or trust boards.
Why This Matters
When boards receive purely operational data, they cannot accurately assess strategic risk. If governors are bogged down in the minutiae of password reset tickets, they are not asking the critical questions about disaster recovery testing, safeguarding filter efficacy, or impending capital expenditure cliffs.
What Good Looks Like
A strategic IT report is concise, evidence-based, and focused entirely on risk, compliance, and strategy. It separates the "what we did" from the "what the board needs to know," translating technical complexity into clear business impacts.
Approach and Methodology
- Elevate the Metrics: Stop reporting on ticket volumes. Start reporting on SLA breaches that impact teaching, critical incident response times, and the status of strategic projects.
- Security and Resilience: Provide a clear RAG (Red, Amber, Green) status on core security controls. Include dates of the most recent backup restore tests, phishing simulations, and vulnerability scans.
- Safeguarding Assurance: Explicitly state the status of web filtering and monitoring systems, confirming they meet DfE statutory guidance (KCSIE). Note any significant outages or configuration changes.
- Financial Forecasting: Include a rolling 3-year view of upcoming capital expenditure (CapEx) requirements, highlighting any end-of-life systems that represent an unfunded risk.
- Compliance Tracking: Report on progress towards external standards, such as Cyber Essentials certification or DfE Digital Standards compliance.
- Acknowledge Risks: Be transparent about accepted risks. If a server cannot be replaced due to budget constraints, document it clearly in the report so the board formally owns the risk.
Evidence to Retain
- Standardised, termly IT reports presented to the board or relevant sub-committee.
- Board minutes reflecting strategic discussions and decisions based on the report.
- An actively managed, board-level IT Risk Register.
Questions Leadership Should Ask
- "Does this report tell us if our network is actually secure, or does it just tell us that the IT team is busy?"
- "Based on this report, do we know what our largest unfunded IT risk is for the next academic year?"
Common Pitfalls
- Technobabble: Blinding the board with acronyms and technical jargon to avoid scrutiny.
- The Good News Only Report: Hiding near-misses, security incidents, or failing infrastructure from the board to avoid difficult conversations.
- Lack of Benchmarking: Presenting data without context. (e.g., Is 50 blocked cyber attacks a day normal, high, or low?)
How asitplan Can Help
asitplan allows IT leaders to generate executive-level dashboards directly from live technical data. Instead of spending days manually compiling a termly report, leaders can present a verifiable, real-time view of asset compliance and infrastructure health directly to the board.